The Cyber Resilience Act, Regulation (EU) 2024/2847, sets administrative fines of up to EUR 15 000 000 or 2.5% of worldwide annual turnover. That figure gets quoted a lot and it is the top of three tiers, not a single number. Which tier an infringement falls into is written out in Article 64, and for a company placing one product on the EU market the difference between the tiers is most of the answer.
Two dates matter before any of it: Article 14 applies from 11 September 2026, and the rest of the Regulation from 11 December 2027. Chapter IV, the notified-body regime, has applied since 11 June 2026. Those are set in Article 71(2).
The three tiers
Up to EUR 15 000 000, or 2.5% of total worldwide annual turnover, whichever is higher. Article 64(2). This covers non-compliance with the essential cybersecurity requirements in Annex I, and the obligations in Articles 13 and 14. Annex I is the security requirements themselves and the vulnerability-handling requirements; Article 13 is the manufacturer's obligations; Article 14 is the reporting duty that starts on 11 September 2026.
Up to EUR 10 000 000, or 2%. Article 64(3). A list of specific articles: 18 to 23, 28, 30(1) to (4), 31(1) to (4), 32(1), (2) and (3), 33(5), and 39, 41, 47, 49 and 53. Articles 18 to 23 are the ones covering everybody in the chain who is not the manufacturer: authorised representatives (18), importers (19), distributors (20), the cases where a manufacturer's obligations transfer to an importer or distributor (21 and 22), and identification of economic operators (23). This is the tier a company that resells someone else's product sits in.
Up to EUR 5 000 000, or 1%. Article 64(4). Supplying incorrect, incomplete or misleading information to a notified body or a market surveillance authority in reply to a request.
The "whichever is higher" only bites above a certain size. 2.5% of turnover exceeds EUR 15 million at around EUR 600 million of revenue, so for anything smaller than that the cash ceiling is the binding one, and it is a ceiling rather than a tariff.
Who actually fines you
Not the Commission. Article 52(2) requires each Member State to designate one or more market surveillance authorities, and lets them use an existing authority or create a new one. Enforcement is national, under Regulation (EU) 2019/1020, the general market surveillance regulation.
One consequence is worth knowing. Article 64(6) requires an authority that imposes a fine to tell the market surveillance authorities of every other Member State, through the information system in Article 34 of Regulation (EU) 2019/1020. A penalty in one country is visible to the others.
Where the Regulation names small manufacturers
Three times, and they are worth knowing because they cut in different directions.
Article 64(5)(c) makes size a factor in the fine. When deciding the amount, due regard must be given to "the size, in particular with regard to microenterprises and small and medium sized-enterprises, including start-ups, and the market share of the economic operator committing the infringement". That is in the enacting text, not a recital. It does not exempt anyone, and the tiers above still apply, but the authority setting the figure is required to take account of what you are.
Article 33(5) lets you file less paperwork. Microenterprises and small enterprises may provide all the elements of the technical documentation in Annex VII using a simplified format. The Commission specifies that form by implementing act, and notified bodies are required to accept it. The obligation there is on the notified body, not on you.
Article 64(10)(a) takes the 24-hour deadline off the fines table for the smallest. By way of derogation from the fine tiers, the administrative fines do not apply to manufacturers that qualify as microenterprises or small enterprises for a failure to meet the early-warning deadline in Article 14(2)(a) or (4)(a). The duty still exists and the other corrective measures remain; what a small manufacturer cannot be fined for is being late with the first 24-hour message. The 72-hour notification and the final report are not covered by the derogation. (The same paragraph, point (b), exempts open-source software stewards from the fines altogether.)
Article 33 also requires Member States to run awareness and training activities for small manufacturers, to open a dedicated channel for their questions, and to support testing and conformity assessment. Whether your Member State has done any of that yet is a fair question to ask it.
What none of this changes
The reporting clock. Article 14 requires an early warning within 24 hours of becoming aware of an actively exploited vulnerability, and it is in the top penalty tier. The clock runs from awareness, which is a thing about your organisation rather than about the vulnerability, so the record of when you became aware is the record that matters. We have written the deadlines out, with the two destinations and the three deadlines.
The report goes to a CSIRT designated as coordinator for the Member State of your main establishment, and to ENISA. We publish the national CSIRT of each of the 27 Member States, read from the CSIRTs Network's own member API, with the caveat that the Article 12 coordinator designations under NIS2 have not been published yet: in most states the coordinator will be the national team, but the table says who the national CSIRT is, not who the coordinator is.
The practical reading
For a small manufacturer, the exposure that should shape behaviour is not the EUR 15 million headline. It is that the top tier covers Annex I and Article 14 together, so the same tier that punishes a missing security requirement punishes a missed report, and only one of those two can be fixed in an afternoon. Registering for the reporting platform costs ten minutes and depends on nobody else. The technical file does not, which is why the December 2027 date is the one to plan against and the September 2026 date is the one to be ready for.